Vulnerability GHSA-g5vr-6pgg-74qv
Low Risk
LOW RISK
CVSS Score: 3.8
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
2 months ago
June 22, 2026 at 03:30 PM UTC
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
v10.11.0+incompatible - v10.11.17+incompatible and v11.7.0+incompatible
v10.11.0+incompatible - v10.11.17+incompatible and v11.7.0+incompatible
Summary
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
Details
Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integrations access to deactivate bot accounts via the PUT /api/v4/users/{id}/active API endpoint.. Mattermost Advisory ID: MMSA-2026-00667
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 months ago
Mattermost doesn't validate file ownership and access control in github.com/mattermost/mattermost-server
v10.11.0+incompatible - v10.11.15-rc1+incompatible GO-2026-5817
v10.11.0+incompatible - v10.11.15-rc1+incompatible GO-2026-5817
Unknown
2 months ago
Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions in github.com/mattermost/mattermost-server
v10.11.0+incompatible - v10.11.15-rc1+incompatible GO-2026-5818
v10.11.0+incompatible - v10.11.15-rc1+incompatible GO-2026-5818
Unknown
2 months ago
Mattermost doesn't archive the channel before removing persistent notifications in github.com/mattermost/mattermost-server
v10.11.0+incompatible - v10.11.15-rc1+incompatible GO-2026-5820
v10.11.0+incompatible - v10.11.15-rc1+incompatible GO-2026-5820
Unknown
2 months ago
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github
v10.11.0+incompatible - v10.11.15-rc1+incompatible GO-2026-5833
v10.11.0+incompatible - v10.11.15-rc1+incompatible GO-2026-5833
Unknown
2 months ago
Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory in github.com/mattermost/mattermost-server
v10.11.0+incompatible - v10.11.15-rc1+incompatible GO-2026-5835
v10.11.0+incompatible - v10.11.15-rc1+incompatible GO-2026-5835
Impacted packages
Timeline
Published
2 months ago
June 22, 2026 at 03:30 PM UTC
Last Modified
1 day ago
September 15, 2026 at 08:00 PM UTC